This, apparently, is a Windows vulnerability. Mac users that run Windows XP or VISTAin either virtualization through Parallels or VMWare's Fusion, or through Boot CampAND use Windows for browsing (It is much safer to browse in OS X), can get their Windows' Clipboards taken over by this exploit. Although this report has appeared in at least three on-line publications, Sophos has no article citing the problem on their website.
Still, a warning is appropriate. PING!
If you want on or off the Mac Ping List, Freepmail me.
I was able to get the test website to load into clipboard while browsing in safari under OSX 10.5.4 on my macbook pro. It also affected 3 versions of firefox running in OSX, Linux (FC6), and XP, all with the NoScript plugin. IE6 and IE7 were affected as well.
Only under IE was it able to use the clipboard to load the “evil” url. So it’s not as effective on Linux/OS X but it can get part of the way there.